Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-1401

Опубликовано: 11 апр. 2011
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 3.5

Описание

ikiwiki before 3.20110328 does not ascertain whether the htmlscrubber plugin is enabled during processing of the "meta stylesheet" directive, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted Cascading Style Sheets (CSS) token sequences in (1) the default stylesheet or (2) an alternate stylesheet.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

3.20110430ubuntu1
hardy

ignored

end of life
karmic

ignored

end of life
lucid

ignored

end of life
maverick

ignored

end of life
natty

ignored

end of life
oneiric

not-affected

3.20110430ubuntu1
precise

not-affected

3.20110430ubuntu1
quantal

not-affected

3.20110430ubuntu1

Показывать по

Ссылки на источники

EPSS

Процентиль: 59%
0.00385
Низкий

3.5 Low

CVSS2

Связанные уязвимости

nvd
больше 14 лет назад

ikiwiki before 3.20110328 does not ascertain whether the htmlscrubber plugin is enabled during processing of the "meta stylesheet" directive, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted Cascading Style Sheets (CSS) token sequences in (1) the default stylesheet or (2) an alternate stylesheet.

debian
больше 14 лет назад

ikiwiki before 3.20110328 does not ascertain whether the htmlscrubber ...

github
больше 3 лет назад

ikiwiki before 3.20110328 does not ascertain whether the htmlscrubber plugin is enabled during processing of the "meta stylesheet" directive, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted Cascading Style Sheets (CSS) token sequences in (1) the default stylesheet or (2) an alternate stylesheet.

EPSS

Процентиль: 59%
0.00385
Низкий

3.5 Low

CVSS2